git: 9cf774a577ab - main - cxgbe: Add a sysctl/tunable to control KTLS offload of AES-CBC cipher suites
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Wed, 30 Sep 2026 20:53:46 UTC
The branch main has been updated by jhb:
URL: https://cgit.FreeBSD.org/src/commit/?id=9cf774a577abbe28e03a849d1ec25f47827f07e6
commit 9cf774a577abbe28e03a849d1ec25f47827f07e6
Author: John Baldwin <jhb@FreeBSD.org>
AuthorDate: 2026-09-30 20:50:12 +0000
Commit: John Baldwin <jhb@FreeBSD.org>
CommitDate: 2026-09-30 20:50:12 +0000
cxgbe: Add a sysctl/tunable to control KTLS offload of AES-CBC cipher suites
Disable these by default as they are less efficient and rarely used.
Sponsored by: Chelsio Communications
---
sys/dev/cxgbe/crypto/t6_kern_tls.c | 7 ++++---
sys/dev/cxgbe/crypto/t7_kern_tls.c | 7 ++++---
sys/dev/cxgbe/offload.h | 1 +
sys/dev/cxgbe/t4_main.c | 11 ++++++++++-
4 files changed, 19 insertions(+), 7 deletions(-)
diff --git a/sys/dev/cxgbe/crypto/t6_kern_tls.c b/sys/dev/cxgbe/crypto/t6_kern_tls.c
index 584e5015acfa..1ebe536b4a43 100644
--- a/sys/dev/cxgbe/crypto/t6_kern_tls.c
+++ b/sys/dev/cxgbe/crypto/t6_kern_tls.c
@@ -383,6 +383,8 @@ t6_tls_tag_alloc(if_t ifp, union if_snd_tag_alloc_params *params,
int atid, error, explicit_iv_size, keyid, mac_first;
tls = params->tls.tls;
+ vi = if_getsoftc(ifp);
+ sc = vi->adapter;
/* Only TLS 1.1 and TLS 1.2 are currently supported. */
if (tls->params.tls_vmajor != TLS_MAJOR_VER_ONE ||
@@ -410,6 +412,8 @@ t6_tls_tag_alloc(if_t ifp, union if_snd_tag_alloc_params *params,
default:
return (EPROTONOSUPPORT);
}
+ if (!sc->tlst.cbc)
+ return (EPROTONOSUPPORT);
explicit_iv_size = AES_BLOCK_LEN;
mac_first = 1;
break;
@@ -431,9 +435,6 @@ t6_tls_tag_alloc(if_t ifp, union if_snd_tag_alloc_params *params,
return (EPROTONOSUPPORT);
}
- vi = if_getsoftc(ifp);
- sc = vi->adapter;
-
tlsp = alloc_tlspcb(ifp, vi, M_WAITOK);
atid = alloc_atid(sc, tlsp);
diff --git a/sys/dev/cxgbe/crypto/t7_kern_tls.c b/sys/dev/cxgbe/crypto/t7_kern_tls.c
index f01a346644af..35342399b468 100644
--- a/sys/dev/cxgbe/crypto/t7_kern_tls.c
+++ b/sys/dev/cxgbe/crypto/t7_kern_tls.c
@@ -160,6 +160,8 @@ t7_tls_tag_alloc(struct ifnet *ifp, union if_snd_tag_alloc_params *params,
uint32_t flowid;
tls = params->tls.tls;
+ vi = if_getsoftc(ifp);
+ sc = vi->adapter;
/* TLS 1.1 through TLS 1.3 are currently supported. */
if (tls->params.tls_vmajor != TLS_MAJOR_VER_ONE ||
@@ -187,6 +189,8 @@ t7_tls_tag_alloc(struct ifnet *ifp, union if_snd_tag_alloc_params *params,
default:
return (EPROTONOSUPPORT);
}
+ if (!sc->tlst.cbc)
+ return (EPROTONOSUPPORT);
iv_size = AES_BLOCK_LEN;
mac_first = 1;
break;
@@ -212,9 +216,6 @@ t7_tls_tag_alloc(struct ifnet *ifp, union if_snd_tag_alloc_params *params,
return (EPROTONOSUPPORT);
}
- vi = if_getsoftc(ifp);
- sc = vi->adapter;
-
tlsp = alloc_tlspcb(ifp, vi, M_WAITOK);
/*
diff --git a/sys/dev/cxgbe/offload.h b/sys/dev/cxgbe/offload.h
index d63accf86e2a..d0508ada2fcb 100644
--- a/sys/dev/cxgbe/offload.h
+++ b/sys/dev/cxgbe/offload.h
@@ -229,6 +229,7 @@ struct iw_tunables {
};
struct tls_tunables {
+ int cbc;
int inline_keys;
union {
struct {
diff --git a/sys/dev/cxgbe/t4_main.c b/sys/dev/cxgbe/t4_main.c
index 27aa2c56d9ec..c91120c85e07 100644
--- a/sys/dev/cxgbe/t4_main.c
+++ b/sys/dev/cxgbe/t4_main.c
@@ -748,11 +748,16 @@ TUNABLE_INT("hw.cxgbe.cop_managed_offloading", &t4_cop_managed_offloading);
*/
static int t4_kern_tls = 0;
SYSCTL_INT(_hw_cxgbe, OID_AUTO, kern_tls, CTLFLAG_RDTUN, &t4_kern_tls, 0,
- "Enable KERN_TLS mode for T6 adapters");
+ "Enable KERN_TLS mode for T6+ adapters");
SYSCTL_NODE(_hw_cxgbe, OID_AUTO, tls, CTLFLAG_RD | CTLFLAG_MPSAFE, 0,
"cxgbe(4) KERN_TLS parameters");
+static int t4_tls_cbc = 0;
+SYSCTL_INT(_hw_cxgbe_tls, OID_AUTO, cbc, CTLFLAG_RDTUN,
+ &t4_tls_cbc, 0,
+ "Enable offload of AES-CBC cipher suites.");
+
static int t4_tls_inline_keys = 0;
SYSCTL_INT(_hw_cxgbe_tls, OID_AUTO, inline_keys, CTLFLAG_RDTUN,
&t4_tls_inline_keys, 0,
@@ -6274,6 +6279,7 @@ set_params__post_init(struct adapter *sc)
#ifdef KERN_TLS
if (is_ktls(sc)) {
+ sc->tlst.cbc = t4_tls_cbc;
sc->tlst.inline_keys = t4_tls_inline_keys;
if (t4_kern_tls != 0 && is_t6(sc)) {
sc->tlst.combo_wrs = t4_tls_combo_wrs;
@@ -8251,6 +8257,9 @@ t4_sysctls(struct adapter *sc)
CTLFLAG_RD | CTLFLAG_MPSAFE, NULL, "KERN_TLS parameters");
children = SYSCTL_CHILDREN(oid);
+ SYSCTL_ADD_INT(ctx, children, OID_AUTO, "cbc",
+ CTLFLAG_RW, &sc->tlst.cbc, 0,
+ "Enable offload of AES-CBC cipher suites.");
SYSCTL_ADD_INT(ctx, children, OID_AUTO, "inline_keys",
CTLFLAG_RW, &sc->tlst.inline_keys, 0, "Always pass TLS "
"keys in work requests (1) or attempt to store TLS keys "